EP3837820A1 - Method of managing the connectivity of a security element to a cellular telecommunications network - Google Patents
Method of managing the connectivity of a security element to a cellular telecommunications networkInfo
- Publication number
- EP3837820A1 EP3837820A1 EP19749366.1A EP19749366A EP3837820A1 EP 3837820 A1 EP3837820 A1 EP 3837820A1 EP 19749366 A EP19749366 A EP 19749366A EP 3837820 A1 EP3837820 A1 EP 3837820A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- sim
- network
- lot
- telecommunications network
- parameter
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
- 238000000034 method Methods 0.000 title claims abstract description 20
- 230000001413 cellular effect Effects 0.000 title description 4
- 239000000725 suspension Substances 0.000 claims description 12
- 238000012986 modification Methods 0.000 claims description 6
- 230000004048 modification Effects 0.000 claims description 6
- 238000004891 communication Methods 0.000 description 14
- 230000011664 signaling Effects 0.000 description 8
- 239000008186 active pharmaceutical agent Substances 0.000 description 3
- 230000006399 behavior Effects 0.000 description 3
- 238000001514 detection method Methods 0.000 description 3
- 230000004913 activation Effects 0.000 description 1
- 230000015556 catabolic process Effects 0.000 description 1
- 230000002950 deficient Effects 0.000 description 1
- 238000006731 degradation reaction Methods 0.000 description 1
- 230000003111 delayed effect Effects 0.000 description 1
- 230000003116 impacting effect Effects 0.000 description 1
- 239000000523 sample Substances 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/02—Access restriction performed under specific conditions
-
- G—PHYSICS
- G16—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
- G16Y—INFORMATION AND COMMUNICATION TECHNOLOGY SPECIALLY ADAPTED FOR THE INTERNET OF THINGS [IoT]
- G16Y10/00—Economic sectors
- G16Y10/75—Information technology; Communication
-
- G—PHYSICS
- G16—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
- G16Y—INFORMATION AND COMMUNICATION TECHNOLOGY SPECIALLY ADAPTED FOR THE INTERNET OF THINGS [IoT]
- G16Y30/00—IoT infrastructure
- G16Y30/10—Security thereof
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/183—Processing at user equipment or user record carrier
Definitions
- the present invention concerns loT Devices and more precisely a method for managing radio connection of such loT Devices with cellular telecommunications networks.
- An loT Device comprises:
- An loT Device Application which is the application software component of the loT Device that controls the Communications Module and interacts with an loT Service Platform via the Communications Module.
- a Communication Module which is the communications component that provides radio connectivity (2G, 3G, 4G or 5G). It comprises Communications Module Firmware, Radio Baseband Chipset and a LJICC.
- o Communications Module Firmware is the functionality within the Communications Module that provides an API to the loT Device Application and controls the Radio Baseband Chipset.
- the Radio Baseband Chipset is the functionality within the Communications Module that provides connectivity to the mobile network.
- the UICC Universal Integrated Circuit Card
- the UICC is the secure element (which can be removable, embedded or integrated) used by a mobile network to authenticate devices for connection to the mobile network and access to network services. It includes the (U)SIM (Subscriber Identity Module) which is the Module provided by the Mobile Network Operator containing the International Mobile Subscriber Identity (IMSI) and the security parameters used to authenticate the (U)SIM with the Network.
- the SIM is seen as an authentication application contained in the UICC.
- the loT Device communicates with an loT Server Application.
- the loT Server Application is an application software component that runs on a server and can exchange data and interact with the loT Devices and the loT Device Applications over the loT Service Platform.
- the loT Service Platform hosted by the loT Service Provider which communicates to an loT Device to provide an loT Service.
- the loT Service Platform can exchange data with the loT Device Application over the Mobile Network and through the Communication Module, using (among others), 2G, 3G, 4G, 5G connectivity including (among others) IP-based protocols over a packet-switched data channel.
- the loT Service Platform typically offers APIs for loT Server Applications to exchange data and interact with the loT Device Applications over the loT Service Platform.
- loT Devices face a default of communication with its loT Server Application (for example due to loT Service Platform overload or default of communication service) the loT Devices continue trying to communicate with the loT Server Application.
- the predicted large scale growth of loT Devices and their associated loT Device Applications will then create major challenges for Mobile Network Operators.
- One major challenge that Mobile Network Operators must overcome is the risk caused by the mass deployment of inefficient, insecure or defective loT Devices on the Mobile Network Operators’ networks. When deployed on a mass scale such devices can cause network signalling traffic to increase to a level which impacts network services for all users of the mobile network. In the worst cases the mass deployment of such loT Devices can disable a mobile network completely.
- An loT Device overusing the network may lead to problems such as:
- loT Server Application suddenly and unexpectedly stopped acknowledging the status reports from the loT Devices.
- loT Devices treated this as a loss of connectivity over their Ethernet network connections and in an attempt to regain connectivity with the loT Server Application the loT Devices all started to‘fall-back’ to a GSM/GPRS network connection.
- loT Devices would reset the GSM/GPRS communication modules, forcing them to re-register to the local GSM/GPRS network and the loT Devices would try again to contact the loT Server Application.
- all loT Devices ended up in an infinite loop with their GSM/GPRS modems being rebooted every minute or so.
- the invention proposes a method of managing the connectivity to a mobile telecommunications network of a SIM cooperating with an loT Device, the method consisting in modifying a parameter of the SIM to temporarily avoid it from connecting to the mobile telecommunications network during a certain period of time.
- This parameter can be the MCC / MNC of the network to which the SIM connects.
- This MCC / MNC is preferably set to 001/01.
- Another solution is to set the MCC / MNC to a different Mobile Operator code than the Home Network.
- Another solution is to modify the ACC file (Access Control Class) of the SIM, this parameter being set to 0 so that the priority of the SIM to connect to the network is nil.
- the method of the invention can be implemented by an applet installed in the security element or by the mobile telecommunications network.
- the period of time can be random or defined within a time interval.
- the invention also concerns a SIM for cooperating with an loT Device, this SIM comprising an applet capable of triggering the suspension of the modification and / or modifying a parameter of the SIM to temporarily prohibit it to connect to a mobile telecommunications network.
- the invention also concerns an element of a mobile telecommunications network, this element comprising a unit able to trigger the suspension of the modification and / or to modify a parameter of a SIM cooperating with an loT Device, in order to temporarily prohibit it from connecting to the mobile telecommunications network.
- the present invention will be better understood by reading the following description of a preferred embodiment of the invention.
- the invention proposes multiple steps to protect the Network
- the invention proposes that the trigger to suspend the loT Device can be automatic or self- decided in order to prevent risk of network overload.
- the automatic detection or loT Device erratic behaviour can be done either from the network side of independently from the loT Device side.
- From the network side network probes can be used on different signalling APIs to monitor the signalling traffic on different network elements (such as HSS or GGSN) and trigger a suspension request when programmable thresholds are hit.
- network elements such as HSS or GGSN
- an applet can monitor the attachment attend (example network attachment or PDP context activation) and trigger a suspension request when programmable thresholds are hit.
- the invention proposes that the loT Device can be suspended permanently or temporally. If the loT Device has to be suspended temporally, the period of time can be calculated randomly between a minimum time and a maximum time either by a server or by the applet itself which will perform the suspension. The minimum and maximum time can be programmable.
- the period of time can be number of“get status” cycle.
- the invention proposes to manage one or several SIM parameters managing the connectivity of the loT Device with his home network.
- This home network is the network from which the owner of the loT Device has bought a subscription.
- step#1 When the trigger is received (as defined in step#1 ) the parameters are temporally changed during the period of time defined in step#3 detailed above.
- the parameters can be changed either by a server (such an Over The Air / OTA platform) or by an applet integrated in the SIM.
- the following parameters can be changed to suspend the connection of the IOT Device: Modify the IMSI, more precisely the MCC / MNC of the network (home network) to which the SIM connects. So, the network to which the SIM will try to connect is no more his home network, but a foreign network. This solution will surely overload the foreign network, but not the home network. In order not to overload the network of another MNO, it is possible to set the MCC / MNC to 001/01. This corresponds to a test network. The loT Device will then no more try to connect to any network for a given period of of time.
- a SIM refresh may be performed in order for the loT Device to consider the new values of the modified parameters.
- the invention proposes that after the period of time is over an applet in the SIM switches back the modified parameters to their respective initial value.
- a SIM refresh may be performed in order for the loT Device to re-consider the new values of the modified parameters.
- the element of the network which manages remotely the SIM card can either be a unit of an OTA platform sending commands through SMS (when the device is already attached to the network) or a proxy HLR which can send parameters through signalling messages during authentication flows (when the device is requesting to attach and is not attached yet).
- the method of the invention can thus be implemented by an applet installed in the security element or by the mobile telecommunications network.
- the invention also concerns a SIM for cooperating with an loT Device, this SIM comprising an applet capable of triggering the suspension of the modification and / or modifying a parameter of the SIM to temporarily prohibit it to connect to a mobile telecommunications network.
- the invention concerns an element of a mobile telecommunications network, this element comprising a unit able to trigger the suspension of the modification and / or to modify a parameter of a SIM cooperating with an loT Device, in order to temporarily prohibit it from connecting to the mobile telecommunications network.
- the main advantage of the invention is that the loT Devices are forced not to generate signalling traffic even if the loT Devices (including application and module) have bad designs or have been subject to fraud.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Development Economics (AREA)
- Economics (AREA)
- General Business, Economics & Management (AREA)
- Databases & Information Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP18306111.8A EP3611894A1 (en) | 2018-08-13 | 2018-08-13 | Method of managing the connectivity of a security element to a cellular telecommunications network |
| PCT/EP2019/071371 WO2020035399A1 (en) | 2018-08-13 | 2019-08-08 | Method of managing the connectivity of a security element to a cellular telecommunications network |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3837820A1 true EP3837820A1 (en) | 2021-06-23 |
Family
ID=63914976
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP18306111.8A Withdrawn EP3611894A1 (en) | 2018-08-13 | 2018-08-13 | Method of managing the connectivity of a security element to a cellular telecommunications network |
| EP19749366.1A Ceased EP3837820A1 (en) | 2018-08-13 | 2019-08-08 | Method of managing the connectivity of a security element to a cellular telecommunications network |
Family Applications Before (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP18306111.8A Withdrawn EP3611894A1 (en) | 2018-08-13 | 2018-08-13 | Method of managing the connectivity of a security element to a cellular telecommunications network |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20210297932A1 (en) |
| EP (2) | EP3611894A1 (en) |
| WO (1) | WO2020035399A1 (en) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112261639B (en) * | 2020-09-21 | 2024-06-14 | 西安广和通无线通信有限公司 | SIM card function configuration method, device, terminal equipment and storage medium |
Family Cites Families (19)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9167471B2 (en) * | 2009-05-07 | 2015-10-20 | Jasper Technologies, Inc. | System and method for responding to aggressive behavior associated with wireless devices |
| US8391161B1 (en) * | 2009-05-07 | 2013-03-05 | Jasper Wireless, Inc. | Virtual diagnostic system for wireless communications network systems |
| CA2812954C (en) * | 2010-09-28 | 2018-05-01 | Research In Motion Limited | Residential/enterprise network connection management and handover scenarios |
| US20120281530A1 (en) * | 2010-11-08 | 2012-11-08 | Qualcomm Incorporated | System and method for radio access network overload control |
| WO2012094591A2 (en) * | 2011-01-07 | 2012-07-12 | Numerex Corp. | Method and system for managing subscriber identity modules on wireless networks for machine-to-machine applications |
| CN102612112B (en) * | 2011-01-21 | 2018-01-30 | 中兴通讯股份有限公司 | A kind of terminal access method and device |
| WO2013137629A1 (en) * | 2012-03-12 | 2013-09-19 | Samsung Electronics Co., Ltd. | Method and system for selective access control with ensured service continuity guarantees |
| EP2939458B1 (en) * | 2012-12-27 | 2018-02-21 | Cisco Technology, Inc. | A system and method for responding to aggressive behavior associated with wireless devices |
| KR20190006607A (en) * | 2014-03-31 | 2019-01-18 | 콘비다 와이어리스, 엘엘씨 | Overload control and coordination between m2m service layer and 3gpp networks |
| US10154366B2 (en) * | 2014-08-18 | 2018-12-11 | Deutsche Telekom Ag | Method and system for exchanging data with a mobile communication network using at least one group of cloned subscriber identity modules |
| US9853777B2 (en) * | 2015-04-06 | 2017-12-26 | Samsung Electronics Co., Ltd | Method for optimizing cell selection in a dual SIM dual standby device |
| US9883546B2 (en) * | 2015-09-04 | 2018-01-30 | Apple Inc. | Postponing a resending of a data service request |
| US9923821B2 (en) * | 2015-12-23 | 2018-03-20 | Intel Corporation | Managing communication congestion for internet of things devices |
| EP3242500A1 (en) * | 2016-05-04 | 2017-11-08 | Gemalto M2M GmbH | Mobile communication device with subscriber identity module |
| CN107426800B (en) * | 2016-05-23 | 2020-12-29 | 中兴通讯股份有限公司 | Method, device and smart card for reducing power consumption of terminal |
| US10568073B2 (en) * | 2016-12-07 | 2020-02-18 | Samsung Electronics Co., Ltd. | Methods and dual SIM dual standby (DSDS) devices for managing data communication |
| EP4117342A1 (en) * | 2017-08-10 | 2023-01-11 | Telefonaktiebolaget LM Ericsson (PUBL) | Service gap control for a wireless device |
| US20210051469A1 (en) * | 2018-02-19 | 2021-02-18 | Freebit Co., Ltd. | Computer software program for controlling data communication and terminal function of portable information terminal, and data communication control server |
| US11510061B1 (en) * | 2020-12-30 | 2022-11-22 | Trend Micro Incorporated | Mitigation of cyberattacks on cellular devices |
-
2018
- 2018-08-13 EP EP18306111.8A patent/EP3611894A1/en not_active Withdrawn
-
2019
- 2019-08-08 US US17/267,051 patent/US20210297932A1/en not_active Abandoned
- 2019-08-08 WO PCT/EP2019/071371 patent/WO2020035399A1/en not_active Ceased
- 2019-08-08 EP EP19749366.1A patent/EP3837820A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| WO2020035399A1 (en) | 2020-02-20 |
| US20210297932A1 (en) | 2021-09-23 |
| EP3611894A1 (en) | 2020-02-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9674691B2 (en) | Polling by universal integrated circuit card for remote subscription | |
| US10555222B2 (en) | Event based eUICC fall-back | |
| US9596593B2 (en) | eUICC subscription change | |
| US9723477B2 (en) | Measurement based eUICC fall-back | |
| US10512003B2 (en) | Subscription fall-back in a radio communication network | |
| WO2005122618A1 (en) | Method and radio communication network for detecting the presence of fraudulent subscriber identity modules | |
| US20260059292A1 (en) | Cellular network connectivity procedures | |
| US10524114B2 (en) | Subscription fall-back in a radio communication network | |
| AU2023328887A1 (en) | Cellular network connectivity device procedures | |
| EP3837820A1 (en) | Method of managing the connectivity of a security element to a cellular telecommunications network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20210315 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: THALES DIS FRANCE SAS |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20230127 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20241204 |